Description
Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 17 Jan 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-17T13:57:51.051Z
Reserved: 2006-06-22T00:00:00.000Z
Link: CVE-2006-3136
Updated: 2024-08-07T18:16:05.875Z
Status : Modified
Published: 2006-06-22T22:06:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-3136
No data.
OpenCVE Enrichment
No data.
Weaknesses